Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC5
CVE-2018-17456漏洞复现(PoC+Exp)
CVE-2018-1745621 Jun 2019
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-261821 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RISK
open
Exploit-DB
EA Origin < 10.5.38 - Remote Code Execution
CVE-2019-12828remotewindows21 Jun 2019
An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and orig
28RISK
open
GitHub PoC9
CVE-2015-3337 ElasticSearch 任意文件读取
CVE-2015-333721 Jun 2019
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, a
50RISK
open
GitHub PoC3
CVE-2017-1000117漏洞复现(PoC+Exp)
CVE-2017-100011720 Jun 2019
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISK
open
GitHub PoC1
wdfcc/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware20 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DBVexDay Proof
Cisco Prime Infrastructure Health Monitor - TarArchive Directory Traversal (Metasploit)
CVE-2019-1821HIGHremotelinux20 Jun 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISK
open
GitHub PoC
OpenSSH 用户名枚举漏洞(CVE-2018-15473)
CVE-2018-15473MEDIUM19 Jun 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
VulnCheck XDB
client-side
CVE-2019-1040MEDIUM19 Jun 2019
Windows NTLM Tampering Vulnerability
45RISK
open
VulnCheck XDB
client-side
CVE-2019-1040MEDIUM18 Jun 2019
Windows NTLM Tampering Vulnerability
45RISK
open
Exploit-DB
Sahi pro 8.x - Cross-Site Scripting
CVE-2018-20472webappsmultiple18 Jun 2019
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.
23RISK
open
Exploit-DB
Sahi pro 8.x - SQL Injection
CVE-2018-20469webappsmultiple18 Jun 2019
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to
28RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-11580CRITICALunder attackransomware18 Jun 2019
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open
GitHub PoC2
oldthree3/CVE-2019-12735-VIM-NEOVIM
CVE-2019-1273518 Jun 2019
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISK
open
Exploit-DB
Sahi pro 7.x/8.x - Directory Traversal
CVE-2018-20470webappsmultiple18 Jun 2019
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerab
50RISK
open
Exploit-DBVexDay Proof
Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (1)
CVE-2019-12181locallinux18 Jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISK
open
Exploit-DB
HC10 HC.Server Service 10.14 - Remote Invalid Pointer Write
CVE-2019-12323doswindows17 Jun 2019
The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS.
23RISK
open
Exploit-DB
Thunderbird ESR < 60.7.XXX - 'icalmemorystrdupanddequote' Heap-Based Buffer Overflow
CVE-2019-11704dosmultiple17 Jun 2019
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when proce
28RISK
open
Exploit-DB
Thunderbird ESR < 60.7.XXX - Type Confusion
CVE-2019-11706dosmultiple17 Jun 2019
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when pro
23RISK
open
Exploit-DB
Thunderbird ESR < 60.7.XXX - 'parser_get_next_char' Heap-Based Buffer Overflow
CVE-2019-11703dosmultiple17 Jun 2019
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing cer
28RISK
open
Exploit-DB
Spring Security OAuth - Open Redirector
CVE-2019-11269MEDIUMwebappsjava17 Jun 2019
Open Redirector in spring-security-oauth2
33RISK
open
Exploit-DB
Spring Security OAuth - Open Redirector
CVE-2019-3778webappsjava17 Jun 2019
Open Redirect in spring-security-oauth2
28RISK
open
Exploit-DB
Thunderbird ESR < 60.7.XXX - 'icalrecur_add_bydayrules' Stack-Based Buffer Overflow
CVE-2019-11705dosmultiple17 Jun 2019
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processin
23RISK
open
Exploit-DBVexDay Proof
Exim 4.87 - 4.91 - Local Privilege Escalation
CVE-2019-10149CRITICALunder attacklocallinux17 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC1
MrAli-Code/CVE-2018-9995_dvr_credentials
CVE-2018-999516 Jun 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC11
CVE-2019-2725 bypass pocscan and exp
CVE-2019-2725HIGHunder attackransomware16 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
CVE-2019-1064 - AppXSVC Local Privilege Escalation
CVE-2019-1064HIGHunder attackransomware16 Jun 2019
Windows Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2019-2725HIGHunder attackransomware16 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC35
weblogic绕过和wls远程执行
CVE-2019-2725HIGHunder attackransomware15 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
Simple Bash shell quick fix CVE-2019-10149
CVE-2019-10149CRITICALunder attack14 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
previouspage 829 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.